Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
#U7a0b#U5e8fv9.9.9.msi

Overview

General Information

Sample name:#U7a0b#U5e8fv9.9.9.msi
renamed because original name is a hash value
Original sample name:v9.9.9.msi
Analysis ID:1584637
MD5:176ac651687962cc7169549e9e1da88e
SHA1:20942514fcf972dc5a56107b663fc01af910c010
SHA256:394ba6d5a7de793c75100dd0a56d523d950788585febe473de778de1a0a6f3ba
Tags:backdoormsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file has nameless sections
Checks for available system drives (often done to infect USB drives)
Creates files inside the system directory
Deletes files inside the Windows folder
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info

Classification

  • System is w10x64
  • msiexec.exe (PID: 6032 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\#U7a0b#U5e8fv9.9.9.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 2324 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 4396 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 318B630E74338EF68D5F81F3A3572D98 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Windows\Installer\MSI2AB6.tmpReversingLabs: Detection: 15%
Source: C:\Windows\Installer\MSI2AB6.tmpVirustotal: Detection: 35%Perma Link
Source: #U7a0b#U5e8fv9.9.9.msiVirustotal: Detection: 28%Perma Link
Source: #U7a0b#U5e8fv9.9.9.msiReversingLabs: Detection: 28%
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

System Summary

barindex
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\532324.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{60061CAF-7DA8-4838-A14F-7721F9D157C3}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI249B.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\532326.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\532326.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI2AB6.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\532326.msiJump to behavior
Source: Joe Sandbox ViewDropped File: C:\Windows\Installer\MSI2AB6.tmp 960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
Source: MSI2AB6.tmp.2.drStatic PE information: Number of sections : 13 > 10
Source: #U7a0b#U5e8fv9.9.9.msiBinary or memory string: OriginalFilenameReachFramework.resources.dll4 vs #U7a0b#U5e8fv9.9.9.msi
Source: MSI2AB6.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0003054372857756
Source: MSI2AB6.tmp.2.drStatic PE information: Section: ZLIB complexity 1.0005326704545454
Source: MSI2AB6.tmp.2.drStatic PE information: Section: ZLIB complexity 1.000135755325112
Source: classification engineClassification label: mal60.winMSI@4/21@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Windows NT\file.datJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DFC218D441E5A6C896.TMPJump to behavior
Source: #U7a0b#U5e8fv9.9.9.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
Source: #U7a0b#U5e8fv9.9.9.msiVirustotal: Detection: 28%
Source: #U7a0b#U5e8fv9.9.9.msiReversingLabs: Detection: 28%
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\#U7a0b#U5e8fv9.9.9.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 318B630E74338EF68D5F81F3A3572D98 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 318B630E74338EF68D5F81F3A3572D98 E Global\MSI0000Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: shfolder.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: #U7a0b#U5e8fv9.9.9.msiStatic file information: File size 8818688 > 1048576
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name:
Source: MSI2AB6.tmp.2.drStatic PE information: section name: entropy: 7.99982688482025
Source: MSI2AB6.tmp.2.drStatic PE information: section name: entropy: 7.994801087757937
Source: MSI2AB6.tmp.2.drStatic PE information: section name: entropy: 7.999784814387319
Source: MSI2AB6.tmp.2.drStatic PE information: section name: entropy: 7.096144873238127
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI2AB6.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI2AB6.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI2AB6.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exe TID: 4992Thread sleep count: 231 > 30Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
DLL Side-Loading
1
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
Software Packing
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets11
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1584637 Sample: #U7a0b#U5e8fv9.9.9.msi Startdate: 06/01/2025 Architecture: WINDOWS Score: 60 15 Multi AV Scanner detection for dropped file 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 PE file has nameless sections 2->19 6 msiexec.exe 75 29 2->6         started        9 msiexec.exe 5 2->9         started        process3 file4 13 C:\Windows\Installer\MSI2AB6.tmp, PE32+ 6->13 dropped 11 msiexec.exe 6->11         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
#U7a0b#U5e8fv9.9.9.msi28%VirustotalBrowse
#U7a0b#U5e8fv9.9.9.msi29%ReversingLabsWin64.Trojan.Generic
SourceDetectionScannerLabelLink
C:\Windows\Installer\MSI2AB6.tmp16%ReversingLabs
C:\Windows\Installer\MSI2AB6.tmp36%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584637
Start date and time:2025-01-06 04:45:11 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 27s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:9
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:#U7a0b#U5e8fv9.9.9.msi
renamed because original name is a hash value
Original Sample Name:v9.9.9.msi
Detection:MAL
Classification:mal60.winMSI@4/21@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .msi
  • Exclude process from analysis (whitelisted): dllhost.exe, RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe
  • Excluded IPs from analysis (whitelisted): 13.107.246.45, 172.202.163.200
  • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
No simulations
No context
No context
No context
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
C:\Windows\Installer\MSI2AB6.tmpSetup64v3.2.6.msiGet hashmaliciousUnknownBrowse
    T1#U5b89#U88c5#U53051.0.5.msiGet hashmaliciousUnknownBrowse
      T1#U5b89#U88c5#U53051.0.6.msiGet hashmaliciousUnknownBrowse
        Setup64v3.6.5.msiGet hashmaliciousUnknownBrowse
          Setup64v2.3.6.msiGet hashmaliciousUnknownBrowse
            #U7a0b#U5e8fv9.3.5.msiGet hashmaliciousUnknownBrowse
              setup64v6.4.5.msiGet hashmaliciousUnknownBrowse
                installer64v6.2.4.msiGet hashmaliciousUnknownBrowse
                  setup64v2.3.5.msiGet hashmaliciousUnknownBrowse
                    setup64v2.4.3.msiGet hashmaliciousUnknownBrowse
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):7003385
                      Entropy (8bit):7.986514970898773
                      Encrypted:false
                      SSDEEP:196608:GB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4Ox:G6TCe30s0nvfcy67yBHLgfVx
                      MD5:7EA088841F97F751D776FDD944609DA8
                      SHA1:D646564A194C288CD07D2E13F57D37266BBF976B
                      SHA-256:5D78B192755982A6F6F5E3B1A3CCF1DCFCD95280815057D2775BB452FB6E7311
                      SHA-512:6DCA5C8DBC8225A1AFB97768F0D34D38A399900C5C9337592E4E0A386D89D4B8B1780D2BC487526A7418BB858AEE07B9D929C9557809B993E7742B63525B5C07
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@.%Z.@.....@.....@.....@.....@.....@......&.{60061CAF-7DA8-4838-A14F-7721F9D157C3}..Setup..#U7a0b#U5e8fv9.9.9.msi.@.....@.....@.....@........&.{2378C340-D6AE-4132-8A6A-87521735BBDD}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}&.{60061CAF-7DA8-4838-A14F-7721F9D157C3}.@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]..".C:\Program Files (x86)\Windows NT\....*.C:\Program Files (x86)\Windows NT\file.dat...._K..._.@A.......j.MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q........................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):1779104
                      Entropy (8bit):7.999903857887916
                      Encrypted:true
                      SSDEEP:24576:4h1dDf+Pf81RL7h6OaEtwp0T3p+ReGxssMtuJu9pbdBLwgZ7ZT52JPVox6rl0FLW:e1Fh1R56S3YhWD1TPhNZT52LSQGFA
                      MD5:9B3881C319F913E1CC12AD199338FC84
                      SHA1:3F46F93F5D396DCA1693556DEEF3054BF8A05DD5
                      SHA-256:DAC0783050BC1B5B374606B93538D0C69A024A7B0461C97A3005637A05B0C48F
                      SHA-512:000FD2447B18846165A75B035226E3BC1CE3A2ED756C653009DBE049629181ED70A45EC32E544821890B3AA4643BF2C678514412C6FA7554C929B81C6194360F
                      Malicious:false
                      Reputation:low
                      Preview:.@S......&h..................R.......".N..;...FJ...WZ.D...o..Mp.f.........i]..-e./.;2..@'...w.O...........(.e.......s.W.t.......(...u...`..T.vd. ...+....6s........0.(.-.....V....-....27......~.L..<.....h....$c..P7=%..U..U..4S..u..P..e......'.E..e......;y)F.........|....../.........e..z..b.Ra..1.`#.#Q.C.-...m....g*...$.....qE.<........ChGO.....o........^....ks..E..|.G.....A>....*._k.id=M.<3..`.AG`.l.......n.....w@t..d..5...%......)w..l...(o...L..j.....F... l...4`uX.H.U..b.....tH.......^m.....z%.N.,....3v..y...M...S.e..7-.@...3.K.......m.p..Y.8.,u.9F.M....kz.H..o^nq..j/6.=...._..Z0(....pi./..b)............v..GQ.`nF.$......~D@......1>.E#..1._..>hqnb]nc..(.'t..a...w.o...$d...>.N..@m.V~....:i..s.c7.&.M............n...u.}.{..4.3~g..Fi.|.0..`....D..QJK4.v.d.w....#.F*.B.5|..u.........,..$m7..P....U.M.]....}b..`...`.....C.... .A.2".}......+P.q..Hh....RW. .t...Oq1N+.(+%.f.A........1F'C.j..*...e.+&...`.j....MVUq.9....\....-.....{U#..]7....1M...
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fhdrreth, Template: Intel;1033, Revision Number: {2378C340-D6AE-4132-8A6A-87521735BBDD}, Create Time/Date: Sun Jan 5 12:23:48 2025, Last Saved Time/Date: Sun Jan 5 12:23:48 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):8818688
                      Entropy (8bit):7.987458489797397
                      Encrypted:false
                      SSDEEP:196608:G1q3R/OB6TCe30s0TxnHPfctFaEfVr7yBh1LRTKfjO:GW46TCe30s01vfcy67yBHLgf6
                      MD5:176AC651687962CC7169549E9E1DA88E
                      SHA1:20942514FCF972DC5A56107B663FC01AF910C010
                      SHA-256:394BA6D5A7DE793C75100DD0A56D523D950788585FEBE473DE778DE1A0A6F3BA
                      SHA-512:3FDBA1F73915A8BCFFD674F892E81E46C3CCE41E65EBD353FC612CA0BB3D20A5ED73B1B14EADC270931A05A46E7FF8FFE5F2DFD52D5B83BF30F0ECC9FA40796F
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fhdrreth, Template: Intel;1033, Revision Number: {2378C340-D6AE-4132-8A6A-87521735BBDD}, Create Time/Date: Sun Jan 5 12:23:48 2025, Last Saved Time/Date: Sun Jan 5 12:23:48 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Category:dropped
                      Size (bytes):8818688
                      Entropy (8bit):7.987458489797397
                      Encrypted:false
                      SSDEEP:196608:G1q3R/OB6TCe30s0TxnHPfctFaEfVr7yBh1LRTKfjO:GW46TCe30s01vfcy67yBHLgf6
                      MD5:176AC651687962CC7169549E9E1DA88E
                      SHA1:20942514FCF972DC5A56107B663FC01AF910C010
                      SHA-256:394BA6D5A7DE793C75100DD0A56D523D950788585FEBE473DE778DE1A0A6F3BA
                      SHA-512:3FDBA1F73915A8BCFFD674F892E81E46C3CCE41E65EBD353FC612CA0BB3D20A5ED73B1B14EADC270931A05A46E7FF8FFE5F2DFD52D5B83BF30F0ECC9FA40796F
                      Malicious:false
                      Reputation:low
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):6997683
                      Entropy (8bit):7.986814861111534
                      Encrypted:false
                      SSDEEP:196608:RB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O9:T6TCe30s0nvfcy67yBHLgfV9
                      MD5:4D436A13323DF6E7CF5CC703D445C28F
                      SHA1:4C9CC4FBD5A09F0D19638A57EAE02C4DB07A43F8
                      SHA-256:6A92CDC5A01BD2B5E4B5DC0EC33F1B0433635A514DA1A3F7837B45AC1FE89DF9
                      SHA-512:5A4C4EC69CA706C3004A30F3941C7C5FACCB1797135F3582B9844439C6CD8BF87450E1A4F7A08D016C469F51D95B9EDFB6AFDBDD03CB6D758CD806E662C26BC0
                      Malicious:false
                      Reputation:low
                      Preview:...@IXOS.@.....@.%Z.@.....@.....@.....@.....@.....@......&.{60061CAF-7DA8-4838-A14F-7721F9D157C3}..Setup..#U7a0b#U5e8fv9.9.9.msi.@.....@.....@.....@........&.{2378C340-D6AE-4132-8A6A-87521735BBDD}.....@.....@.....@.....@.......@.....@.....@.......@......Setup......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{125CBCBA-000D-4311-82CD-4ABABCD734C4}*.C:\Program Files (x86)\Windows NT\file.dat.@.......@.....@.....@........InstallFiles..Copying new files&.File: [1], Directory: [9], Size: [6]...@.%...@.....@......".C:\Program Files (x86)\Windows NT\....1\gujfn150\|Windows NT\......Please insert the disk: ..cab1.cab.@.....@......C:\Windows\Installer\532324.msi.........@........file.dat..l4d..file.dat.@.....@.%...@.......@.............@.........@.....@.....@.8...@.....@.....@.8........_....J..._.@A.......j.MZx.....................@.........................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Category:dropped
                      Size (bytes):6995968
                      Entropy (8bit):7.9868922155503945
                      Encrypted:false
                      SSDEEP:196608:aB6TCe30s0TDnHPfctFaEfVr7yBh1LRTKf4O:y6TCe30s0nvfcy67yBHLgfV
                      MD5:735124825FE57CBDDBC31F3CF1248171
                      SHA1:41A53E432FAD50A43D195334897C23757AB8433A
                      SHA-256:960A0D4E5F5DBBC1C87096C897C4760C475054C5079C106E947E1961A75ED3AC
                      SHA-512:86A01EF85FB13D3C5CE41C1920BC69872C63BB67BA204F917BC68E7640063E56272E0675468756B62FFCD2B49820D6BBBC7D4A2CA0EE30DA9110CBFD3FA6169B
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 16%
                      • Antivirus: Virustotal, Detection: 36%, Browse
                      Joe Sandbox View:
                      • Filename: Setup64v3.2.6.msi, Detection: malicious, Browse
                      • Filename: T1#U5b89#U88c5#U53051.0.5.msi, Detection: malicious, Browse
                      • Filename: T1#U5b89#U88c5#U53051.0.6.msi, Detection: malicious, Browse
                      • Filename: Setup64v3.6.5.msi, Detection: malicious, Browse
                      • Filename: Setup64v2.3.6.msi, Detection: malicious, Browse
                      • Filename: #U7a0b#U5e8fv9.3.5.msi, Detection: malicious, Browse
                      • Filename: setup64v6.4.5.msi, Detection: malicious, Browse
                      • Filename: installer64v6.2.4.msi, Detection: malicious, Browse
                      • Filename: setup64v2.3.5.msi, Detection: malicious, Browse
                      • Filename: setup64v2.4.3.msi, Detection: malicious, Browse
                      Reputation:moderate, very likely benign file
                      Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d....S.........." .....`..........xz....................................................`... ...... ........ ...... ..............`.Q....L|R.\.....5.......R.............@.Q...............................Q.(............................................................`.......<..................@............0...p.......@..............@.................!.....................@............@...05....... .............@................p5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@.................5....... .............@....rsrc.........5....... .............@..@..............5....... .............@............ B...Q...B...(.............@...................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.1688698686731849
                      Encrypted:false
                      SSDEEP:12:JSbX72FjvAGiLIlHVRpRh/7777777777777777777777777vDHFXkWf/bK9+l0i5:JRQI5FRH/kF
                      MD5:365923177CAF1E15251228975750FAE4
                      SHA1:B9C075DB514B2D8B14793D151FCF92DA335B77DD
                      SHA-256:DF6C3B949C0E4E503A92A85AE1750CFCA6CDFC0C884120CFAB4B7F1403F1AA9E
                      SHA-512:6FA7D574A91040F18A8D253E1D7ECE20A9B1FAC677A1A700A01B82347F31A49F48F1DDE38AB044400A818A33B9CBF54172C923FD093351165377FBBA0895B4EB
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4705535294761125
                      Encrypted:false
                      SSDEEP:48:G8PhMuRc06WXJinT5vjA7jjbtdeS5lrCdeSIG:ZhM1ZnTVGj/+yS
                      MD5:CC0C89570983E6BCFF5D7F5C30C74092
                      SHA1:73A155902D6CB6F46178A7FC26B097100859E2DB
                      SHA-256:626F0C3A988F4AE6373F68461E739ECBE34550B88787E9173F0D5237ABA61F3E
                      SHA-512:4F23287DB1F6DDB57F400AB9ABA1A55DAC56410517EF9B799F3B8050DDE554B86358AE03658F2DBCC06F224EC7845C0B6CEDB8284E3788EF28C3A31A88B5E0D2
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):360001
                      Entropy (8bit):5.362984919051602
                      Encrypted:false
                      SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26KgauF:zTtbmkExhMJCIpEU
                      MD5:5162FA814E8101D888C48708D40530A6
                      SHA1:57825E568B7C6A868E15588C70A49DA21AC21925
                      SHA-256:78F738B89A5E63EC4712F4396DEDDC21BE4B5C0C3603509459AE2FA2DC937BFC
                      SHA-512:DEACD1F21AD6036F3CBDDC01DE81E1114BDC0606E575B276F3A6C508127F06D58A738D8478891D8FAFDC12C873099C9D8FB246AAC2595BC55F7D51F5967006EF
                      Malicious:false
                      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):0.07484140422886
                      Encrypted:false
                      SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOXkWf/bHiPRXAVky6l+:2F0i8n0itFzDHFXkWf/bK9+
                      MD5:2C5024B68A0DB7DB799360661B5BA78F
                      SHA1:49A1A81F7840D82FD6D5B8847712BBB30BD5B693
                      SHA-256:377D5AD720758EDB6BB3AA6BCBD341F6D7DEAC0953EAC74CA3A665ADB55A0EBB
                      SHA-512:8C65D4351C87E2BABAA24BB29D5FB305E18A053F59891707FBCF38942C3D4E6D020E634B18DA21070F3F7B4DDAD72C093FB0A337C9724AA934B1E0C7F4D8D57B
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1848547526612778
                      Encrypted:false
                      SSDEEP:48:rnkunNveFXJRT5ljA7jjbtdeS5lrCdeSIG:DkDpT3Gj/+yS
                      MD5:A33DD5E0ECE29313FB16E05E1B7EECEA
                      SHA1:C04A6A3090B6BA9C44A2B24BC1333BD2000A65E7
                      SHA-256:5C508F526C3C03D95810348554481F7FEFEB1665F7D66AD13FA0D61095A82F4A
                      SHA-512:11E0D5A0CEF7DAB8BBEF9D10A7FB4FC428C2EE436F0116F21DED400621B6EEC9EC55A2B9E0F96C148CBA2D59D90FC3B0A310ADB4A36ADAB1E28262390252A5F2
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1848547526612778
                      Encrypted:false
                      SSDEEP:48:rnkunNveFXJRT5ljA7jjbtdeS5lrCdeSIG:DkDpT3Gj/+yS
                      MD5:A33DD5E0ECE29313FB16E05E1B7EECEA
                      SHA1:C04A6A3090B6BA9C44A2B24BC1333BD2000A65E7
                      SHA-256:5C508F526C3C03D95810348554481F7FEFEB1665F7D66AD13FA0D61095A82F4A
                      SHA-512:11E0D5A0CEF7DAB8BBEF9D10A7FB4FC428C2EE436F0116F21DED400621B6EEC9EC55A2B9E0F96C148CBA2D59D90FC3B0A310ADB4A36ADAB1E28262390252A5F2
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4705535294761125
                      Encrypted:false
                      SSDEEP:48:G8PhMuRc06WXJinT5vjA7jjbtdeS5lrCdeSIG:ZhM1ZnTVGj/+yS
                      MD5:CC0C89570983E6BCFF5D7F5C30C74092
                      SHA1:73A155902D6CB6F46178A7FC26B097100859E2DB
                      SHA-256:626F0C3A988F4AE6373F68461E739ECBE34550B88787E9173F0D5237ABA61F3E
                      SHA-512:4F23287DB1F6DDB57F400AB9ABA1A55DAC56410517EF9B799F3B8050DDE554B86358AE03658F2DBCC06F224EC7845C0B6CEDB8284E3788EF28C3A31A88B5E0D2
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):69632
                      Entropy (8bit):0.10558910446052536
                      Encrypted:false
                      SSDEEP:24:cVVXZLdB5GipVGdB5GipV7VgwGolrkgKCL8+6KAQuL:sXldeScdeS5lrKu8jKA1
                      MD5:E6E76ADE1D0C7E0EAB3B6DDAC09D6A31
                      SHA1:08E73A6A80E5BC63BBA0B04226FE3370D06E3606
                      SHA-256:2DB356539261833B62021C72A45D17A802B346012723996420D370B2191A5FE2
                      SHA-512:DA146A17925B053B5C1104E221CEE5E51D37742181F85DF6C719C0E817D855C00F036D246E7BD9ED76F096CD844D337E7F9DD4E4B999634CA87EA711232D55AE
                      Malicious:false
                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):32768
                      Entropy (8bit):1.1848547526612778
                      Encrypted:false
                      SSDEEP:48:rnkunNveFXJRT5ljA7jjbtdeS5lrCdeSIG:DkDpT3Gj/+yS
                      MD5:A33DD5E0ECE29313FB16E05E1B7EECEA
                      SHA1:C04A6A3090B6BA9C44A2B24BC1333BD2000A65E7
                      SHA-256:5C508F526C3C03D95810348554481F7FEFEB1665F7D66AD13FA0D61095A82F4A
                      SHA-512:11E0D5A0CEF7DAB8BBEF9D10A7FB4FC428C2EE436F0116F21DED400621B6EEC9EC55A2B9E0F96C148CBA2D59D90FC3B0A310ADB4A36ADAB1E28262390252A5F2
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:Composite Document File V2 Document, Cannot read section info
                      Category:dropped
                      Size (bytes):20480
                      Entropy (8bit):1.4705535294761125
                      Encrypted:false
                      SSDEEP:48:G8PhMuRc06WXJinT5vjA7jjbtdeS5lrCdeSIG:ZhM1ZnTVGj/+yS
                      MD5:CC0C89570983E6BCFF5D7F5C30C74092
                      SHA1:73A155902D6CB6F46178A7FC26B097100859E2DB
                      SHA-256:626F0C3A988F4AE6373F68461E739ECBE34550B88787E9173F0D5237ABA61F3E
                      SHA-512:4F23287DB1F6DDB57F400AB9ABA1A55DAC56410517EF9B799F3B8050DDE554B86358AE03658F2DBCC06F224EC7845C0B6CEDB8284E3788EF28C3A31A88B5E0D2
                      Malicious:false
                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      Process:C:\Windows\System32\msiexec.exe
                      File Type:data
                      Category:modified
                      Size (bytes):512
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3::
                      MD5:BF619EAC0CDF3F68D496EA9344137E8B
                      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                      Malicious:false
                      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                      File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Setup, Author: Netease, Keywords: Installer, Comments: fhdrreth, Template: Intel;1033, Revision Number: {2378C340-D6AE-4132-8A6A-87521735BBDD}, Create Time/Date: Sun Jan 5 12:23:48 2025, Last Saved Time/Date: Sun Jan 5 12:23:48 2025, Number of Pages: 300, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
                      Entropy (8bit):7.987458489797397
                      TrID:
                      • Microsoft Windows Installer (60509/1) 88.31%
                      • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                      File name:#U7a0b#U5e8fv9.9.9.msi
                      File size:8'818'688 bytes
                      MD5:176ac651687962cc7169549e9e1da88e
                      SHA1:20942514fcf972dc5a56107b663fc01af910c010
                      SHA256:394ba6d5a7de793c75100dd0a56d523d950788585febe473de778de1a0a6f3ba
                      SHA512:3fdba1f73915a8bcffd674f892e81e46c3cce41e65ebd353fc612ca0bb3d20a5ed73b1b14eadc270931a05a46e7ff8ffe5f2dfd52d5b83bf30f0ecc9fa40796f
                      SSDEEP:196608:G1q3R/OB6TCe30s0TxnHPfctFaEfVr7yBh1LRTKfjO:GW46TCe30s01vfcy67yBHLgf6
                      TLSH:3B963325B8AFD3FAF9356B32495072A20142AE7067F285065B057F0D107EB70E77BA6C
                      File Content Preview:........................>......................................................................................................................................................................................................................................
                      Icon Hash:2d2e3797b32b2b99
                      No network behavior found

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:22:46:02
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\#U7a0b#U5e8fv9.9.9.msi"
                      Imagebase:0x7ff66c250000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      Target ID:2
                      Start time:22:46:02
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\msiexec.exe /V
                      Imagebase:0x7ff66c250000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:false

                      Target ID:3
                      Start time:22:46:04
                      Start date:05/01/2025
                      Path:C:\Windows\System32\msiexec.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\System32\MsiExec.exe -Embedding 318B630E74338EF68D5F81F3A3572D98 E Global\MSI0000
                      Imagebase:0x7ff66c250000
                      File size:69'632 bytes
                      MD5 hash:E5DA170027542E25EDE42FC54C929077
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly